Following the briefing on the June 4 unauthorized disclosure, council members asked detailed questions about both quick fixes and long-term safeguards. Several councilmembers urged that internal audit test the new controls and that communications to affected retirees include direct phone outreach beyond 311 scripting. "Call 311 felt inadequate for some retirees," one member said, and staff confirmed a two-tier call system with division chiefs available for escalations.
IT staff described planned investments in data classification to flag large exports of sensitive fields, suppression of full bank account numbers in exports, and data-loss-prevention rules that can block or warn before sending large sets of financial data by email. Staff also acknowledged that encryption alone would not have prevented the human error at issue and said they will assess whether issuing county-domain email accounts to volunteer corps is feasible given administrative cost and account maintenance overhead.
The committee requested that audit include post-implementation testing and that communications be revised to make clearer how affected retirees can get dedicated, one-on-one assistance.